Total
3085 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2012-5111 | 1 Google | 1 Chrome | 2017-09-18 | 7.5 HIGH | N/A |
Google Chrome before 22.0.1229.92 does not monitor for crashes of Pepper plug-ins, which has unspecified impact and remote attack vectors. | |||||
CVE-2013-0903 | 1 Google | 1 Chrome | 2017-09-18 | 7.5 HIGH | N/A |
Use-after-free vulnerability in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of browser navigation. | |||||
CVE-2012-5128 | 2 Google, Linux | 3 Chrome, V8, Linux Kernel | 2017-09-18 | 7.5 HIGH | N/A |
Google V8 before 3.13.7.5, as used in Google Chrome before 23.0.1271.64, does not properly perform write operations, which allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2013-0902 | 1 Google | 1 Chrome | 2017-09-18 | 7.5 HIGH | N/A |
Use-after-free vulnerability in the frame-loader implementation in Google Chrome before 25.0.1364.152 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2012-5108 | 1 Google | 1 Chrome | 2017-09-18 | 9.3 HIGH | N/A |
Race condition in Google Chrome before 22.0.1229.92 allows remote attackers to execute arbitrary code via vectors related to audio devices. | |||||
CVE-2012-5109 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
The International Components for Unicode (ICU) functionality in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via vectors related to a regular expression. | |||||
CVE-2013-0842 | 1 Google | 1 Chrome | 2017-09-18 | 10.0 HIGH | N/A |
Google Chrome before 24.0.1312.56 does not properly handle %00 characters in pathnames, which has unspecified impact and attack vectors. | |||||
CVE-2013-0828 | 1 Google | 1 Chrome | 2017-09-18 | 6.8 MEDIUM | N/A |
The PDF functionality in Google Chrome before 24.0.1312.52 does not properly perform a cast of an unspecified variable during processing of the root of the structure tree, which allows remote attackers to cause a denial of service or possibly have unknown other impact via a crafted document. | |||||
CVE-2013-0829 | 1 Google | 1 Chrome | 2017-09-18 | 6.4 MEDIUM | N/A |
Google Chrome before 24.0.1312.52 does not properly maintain database metadata, which allows remote attackers to bypass intended file-access restrictions via unspecified vectors. | |||||
CVE-2012-5110 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
The compositor in Google Chrome before 22.0.1229.92 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |||||
CVE-2013-0839 | 1 Google | 1 Chrome | 2017-09-18 | 7.5 HIGH | N/A |
Use-after-free vulnerability in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via vectors related to the handling of fonts in CANVAS elements. | |||||
CVE-2013-0841 | 1 Google | 1 Chrome | 2017-09-18 | 7.5 HIGH | N/A |
Array index error in the content-blocking functionality in Google Chrome before 24.0.1312.56 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors. | |||||
CVE-2012-2822 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
The PDF functionality in Google Chrome before 20.0.1132.43 allows remote attackers to cause a denial of service (out-of-bounds read) via unspecified vectors. | |||||
CVE-2011-3886 | 1 Google | 2 Chrome, V8 | 2017-09-18 | 6.8 MEDIUM | N/A |
Google V8, as used in Google Chrome before 15.0.874.102, allows remote attackers to cause a denial of service or possibly have unspecified other impact via crafted JavaScript code that triggers out-of-bounds write operations. | |||||
CVE-2011-4691 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
Google Chrome 15.0.874.121 and earlier does not prevent capture of data about the times of Same Origin Policy violations during IFRAME loading attempts, which makes it easier for remote attackers to determine whether a document exists in the browser cache via crafted JavaScript code. | |||||
CVE-2011-4692 | 2 Apple, Google | 3 Safari, Webkit, Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
WebKit, as used in Apple Safari 5.1.1 and earlier and Google Chrome 15 and earlier, does not prevent capture of data about the time required for image loading, which makes it easier for remote attackers to determine whether an image exists in the browser cache via crafted JavaScript code, as demonstrated by visipisi. | |||||
CVE-2012-2828 | 1 Google | 1 Chrome | 2017-09-18 | 6.8 MEDIUM | N/A |
Multiple integer overflows in the PDF functionality in Google Chrome before 20.0.1132.43 allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted document. | |||||
CVE-2012-2764 | 2 Google, Microsoft | 2 Chrome, Windows | 2017-09-18 | 7.2 HIGH | N/A |
Untrusted search path vulnerability in Google Chrome before 20.0.1132.43 on Windows might allow local users to gain privileges via a Trojan horse Metro DLL in the current working directory. | |||||
CVE-2012-2815 | 1 Google | 1 Chrome | 2017-09-18 | 5.0 MEDIUM | N/A |
Google Chrome before 20.0.1132.43 allows remote attackers to obtain potentially sensitive information from a fragment identifier by leveraging access to an IFRAME element associated with a different domain. | |||||
CVE-2012-2816 | 2 Google, Microsoft | 2 Chrome, Windows | 2017-09-18 | 7.8 HIGH | N/A |
Google Chrome before 20.0.1132.43 on Windows does not properly isolate sandboxed processes, which might allow remote attackers to cause a denial of service (process interference) via unspecified vectors. |